4 ms·
> End users are free to remove them. Let's not pretend we don't know the power of defaults, or that we expect users to learn about and modify the obscure and t
by pannSun 4y ago
> End users are free to remove them.
Let's not pretend we don't know the power of defaults, or that we expect users to learn about and modify the obscure and technical innards of their browsers. Even expert users can be fooled, such as when the NSA bribed a company to default to a weak cipher [1].
> Microsoft, Mozilla and others already provide you with a list of who you’re going to trust by default.
If I use Firefox, I choose to trust Mozilla. But now, whichever browser I choose, I am forced to trust its maker and the government and intelligence agencies of every EU member state.
I can spend my limited time learning how to fix this, but is it legal to share my solution in a convenient form (such as a browser that by-default trusts CAs based on merit, not government order), or would that make me a browser vendor, and compel me to backdoor my software?
This is, in effect, prohibiting cooperation to fight surveillance.
> It would be more outrageous if the current CAs were some sort of gold standard, but the whole system is flawed.
I don't see how the current system being flawed makes a government mandate to default-trust hypothetical known-untrustworthy CAs less bad. It is a red herring - is a system being "flawed" justification for government intrusion? And does this intrusion even attempt to fix those flaws??
[1] https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-million-for-a-back-door-into-rsa-encryption-according-to https://www.theverge.com/2013/12/20/5231006/nsa-paid-10-mill...